Civic / Privacy / Digital Rights
2IA.org Trust, Contact, Corrections, Privacy, and Institutional Identity Audit
Report summary
This audit was conducted on July 26, 2026, at 10:32:57 AM CDT in the America/Chicago time zone, which is UTC−05:00 on that date. For this report, “current through” means the public pages and search/discovery results available at the time of review on July 26, 2026. The site’s own freshness markers a
Key topics
- Civic / Privacy / Digital Rights
- Civic
- Privacy
- Digital Rights
- AI
- .NET
- SQL
- TypeScript
- Angular
Research provenance
For citation, use the report title and canonical URL. Archival presence does not establish authorship or promote report statements into portfolio evidence.
Source availability: 67 citation markers in the source export have no recoverable source links. Those markers are omitted from this reader; any supplied bibliography and ordinary links remain. Check the original sources before relying on the cited claims.
This page renders the archived Markdown as safe, formatted HTML. It is background research and does not become a portfolio claim without evidence review.
Full report
On this page
Executive summary and research scope
This audit was conducted on July 26, 2026, at 10:32:57 AM CDT in the America/Chicago time zone, which is UTC−05:00 on that date. For this report, “current through” means the public pages and search/discovery results available at the time of review on July 26, 2026. The site’s own freshness markers are mixed: core trust pages such as About, Contact, Privacy Policy, Methodology, Public Records and FOIA, and related status pages state “Last reviewed July 26, 2026,” while the homepage says its world-events/current layer runs through July 24, 2026, and the 2IA Daily Brief page said no local synchronized edition was yet available at the time of review.
Pages reviewed for this audit included the homepage, About, Contact, the Lawful Contact redirect target, Corrections and Right of Reply, the downloadable correction template, Privacy Policy, Methodology, Public Records and FOIA, Start Here, Topics, Daily Brief, Newsletter Status, Support Status, Volunteer Status, Cooperating Experts Model, Privacy Repair, Request a Correction, Correction/Update/Source Note, plus externally linked identity references at MikeKappel.com, GitHub, MichaelJosephKappel.com, and a public LinkedIn search preview. These were all reviewed through ordinary public web access only.
The core finding is that 2IA’s current rendered pages now mostly present a coherent “International Intelligence Archive” identity, with repeated disclaimers that the site is independent, information-only, non-operational, and not affiliated with government, intelligence, law enforcement, activists, or Anonymous. That is a meaningful improvement in reader-facing trust language. But the site still has a substantial discovery-layer identity problem: public search results for multiple pages continue to surface the legacy brand “2IA — Two Identities Of Anonymous,” older footer/navigation text, and older project-description language. That means the rebrand is not yet clean in the public record, even if the current page render is cleaner.
The site does a number of trust things well. Its Contact page is real, direct, and explicit that it is not a secure-drop channel. Its Corrections page clearly distinguishes correction, update, clarification, and right of reply. Its Methodology page gives unusually clear public guidance on source origin, corroboration, legal stages, uncertainty, and human responsibility for AI-assisted work. Its privacy stance is restrained and consistent with a site that does not expose active donation, newsletter, or volunteer intake.
The weaker points are structural. Publisher identity is still too inferential, because the site presents Michael Joseph Kappel as the public contact and profile subject, but it does not plainly and repeatedly say, in masthead form, “published by Michael Joseph Kappel” or the equivalent on the homepage, About page, and footer. Corrections process transparency remains incomplete, because there is no visible public corrections log, no response timeline, and no public examples of repairs. Privacy policy completeness is limited, because children’s privacy, policy-change handling, and exact retention periods are missing. Finally, several public subpages under the corrections and volunteer/public-records-adjacent routes show template-like, internal-workflow prose that looks more like editorial scaffolding than reader-ready guidance.
Institutional identity and About-page findings
Institutional-identity findings
On its current rendered pages, the site does identify itself as “2IA — International Intelligence Archive” with notable consistency. The homepage title shown in public rendering is “2IA — International Intelligence Archive | Evidence, Context, and Analysis,” and the same naming pattern appears on About, Contact, Privacy Policy, Methodology, Public Records and FOIA, Start Here, Topics, Newsletter Status, Support Status, and Daily Brief. The homepage body also frames 2IA as an “independent, information-only archive,” and the About page explicitly says “2IA is the International Intelligence Archive.” On the core rendered pages, that claim is OBSERVABLY TRUE.
At the same time, the old phrase “Two Identities Of Anonymous” still visibly persists in the site’s public discovery layer. Search/discovery results for the homepage, About, Contact, Privacy Policy, Start Here, Newsletter, Research Archive, Topics, and related pages still surface titles or snippets using the old brand string. As a matter of public perception, that makes the statement “the site consistently identifies itself only as International Intelligence Archive” OBSERVABLY FALSE. A more accurate classification is that the current render is updated but the public-facing metadata/discovery record is still OUTDATED.
The relationship to Anonymous is substantially clearer on the current trust pages than the legacy brand suggests. The homepage says 2IA “does not represent” Anonymous, and the About page says “Anonymous is a research collection” and that 2IA “does not represent Anonymous or speak for people who use the label.” The Anonymous Research Collection page reinforces that by treating Anonymous as a contested, decentralized label requiring source-specific attribution rather than as a unified actor or publisher. The trust claim “Anonymous is clearly a research collection rather than the publisher” is therefore CLEAR AND USEFUL on current pages, though it is still partially undermined by legacy discovery branding that keeps the old name alive.
The site repeatedly states that it is not affiliated with a government, intelligence service, law-enforcement body, activist movement, political campaign, or Anonymous. Those disclaimers are strong communication. But the factual truth of non-affiliation is not something a public page can fully prove from the outside. So the trust claim “2IA is not affiliated with these actors” is best classified as NOT PUBLICLY VERIFIABLE, even though the way the site communicates that boundary is clear and helpful.
The larger institutional-boundary problem is not overt false affiliation; it is semantic blur. “International Intelligence Archive,” “Daily Brief,” and the sister publication “International Intelligence — news and real-time intelligence” all carry intelligence-reporting connotations. The site does offset that with explicit disclaimers and with repeated “independent” and “information-only” language. But because the publisher’s human identity is not front-footed across the masthead, a first-time reader can still understand the mission before they fully understand who is speaking. That makes the claim “institutional boundaries are plain and credible” PARTIALLY SUPPORTED.
About-page findings
The About page is among the site’s strongest trust surfaces. It states scope, limits, non-affiliation, Anonymous-as-collection, privacy-forward design, and the site’s non-operational posture in compact and readable language. The claim “the About page helps a reasonable reader understand what 2IA is and is not” is CLEAR AND USEFUL.
What the About page does not do is plainly answer the publisher question. It describes the publication, but it does not prominently say “published by Michael Joseph Kappel” or give a concise masthead-style owner statement. A reader has to infer authorship or control by moving from About to Contact. So the trust claim “the publisher’s identity is clear from the About page” is PARTIALLY SUPPORTED rather than fully satisfied.
Footer and metadata consistency
Publicly rendered page titles now align well with the updated “International Intelligence Archive” naming. The visible issue is not the current page title itself; it is the publicly exposed discovery layer. Search results still show old page titles and old project descriptions, sometimes alongside newer rendered content. That means title tags, indexable summaries, and likely other metadata have not fully converged in the public record. The trust claim “footer, title tags, About copy, and social/discovery metadata agree” is therefore OBSERVABLY FALSE from the standpoint of what a normal reader can encounter in search.
On some search results for older/related pages, the snippets also surface what looks like older footer or sitewide navigational material, such as “Support,” “Newsletter,” and “Volunteer,” as well as legacy copyright/branding strings. Since the current service-status pages say donations, newsletter signup, and volunteer intake are inactive, these discovery snippets preserve a mixed public impression. The trust claim “footer identity is stable and current” is OUTDATED in practice, even where the live page render is cleaner.
The same caution applies to social metadata. It was not fully inspectable from the public page-rendering interface used here, so any precise claim about current OG/Twitter tags would be beyond what can be responsibly stated from this audit alone. The trust claim “social metadata is synchronized with current visible branding” is therefore NOT PUBLICLY VERIFIABLE on the evidence reviewed here, though the discovery-layer inconsistency strongly suggests it may not be fully synchronized in practice.
Contact, publisher attribution, and personal-profile accuracy
Contact Us findings
The Contact page provides a real, ordinary public contact route. It publishes a direct email address, direct phone number, external professional website, and a postal address, and it explicitly says what those channels are for: ordinary questions, documented corrections, research discussion, software architecture, or related collaboration. The trust claim “Contact Us provides a genuine contact route” is OBSERVABLY TRUE.
The same page clearly identifies the public contact as Michael Joseph Kappel / Michael Kappel. That identity is reinforced by the linked external portfolio, which uses the same email address, phone number, city, and professional profile; by the public GitHub profile, which uses the full name “Michael Joseph Kappel”; and by a LinkedIn search preview that describes him as a senior software engineer/software architect with over 20 years of experience. The trust claim “the page accurately identifies Michael Joseph Kappel” is PARTIALLY SUPPORTED by multiple public corroborators. It is not a legal identity verification, but there is no visible contradiction.
The email address, phone number, and broad location signal are consistent between 2IA Contact and MikeKappel.com. The 2IA page publishes the full mailing address and states that it is published at Michael Kappel’s request; MikeKappel.com publicly shows the same email address, the same phone number, and “Cicero, IL.” The trust claim “the email, website, phone, and address/location are presented consistently” is OBSERVABLY TRUE at the level of contact identity and city-level location consistency.
The page also properly warns that it is not a secure disclosure system. It says not to send classified information, stolen data, credentials, exploit details, threats, or private data about other people, and it explicitly says there is no Signal account, PGP key, anonymous upload route, or secure drop. That is one of the site’s clearest and best trust practices. The trust claim “the site avoids a misleading secure-drop implication” is CLEAR AND USEFUL.
The inquiry taxonomy is reasonably clear, but the Contact page still blends too many roles into one surface. It functions simultaneously as a publisher contact page, corrections route, public-interest publishing profile, software-architecture profile, AI-workflow profile, photography cross-link page, and general professional identity page. That does not make it false, but it does reduce editorial clarity. The trust claim “the page cleanly separates general profile from publication contact” is only PARTIALLY SUPPORTED.
Personal-profile accuracy and privacy implications
The broad biographical claims on the Contact page are not obviously invented. MikeKappel.com supports the same positioning: senior software engineer/software architect, .NET and SQL modernization, TypeScript/Angular, AI-assisted engineering, 20+ years, contact details, and city. The GitHub profile supports the name and website association, and the LinkedIn preview supports the seniority claim. So the trust claim “the page avoids invented credentials or unsupported biography” is PARTIALLY SUPPORTED leaning positive.
The page directly says employment history and employer names are intentionally omitted, and the external portfolio also frames itself as an evidence-backed portfolio rather than a certification surface. That restraint is good. The trust claim “the page separates profile summary from employment-history detail” is OBSERVABLY TRUE.
The privacy tradeoff is sharper. The Contact page publicly displays a residential mailing address and says that choice was made at Michael Kappel’s request. Because the page is a publisher-contact surface rather than only a personal portfolio, that is an intentional self-disclosure rather than an accidental leak. Even so, it expands the personal-data footprint of the publisher beyond what is strictly necessary for most editorial contact. The trust claim “the page avoids exposing unnecessary personal information beyond the publisher’s stated choice” is PARTIALLY SUPPORTED: the disclosure is explicitly chosen, but it is still more exposure than the site otherwise advocates for others.
The visible contact actions themselves are accessible to ordinary readers because the email address, phone number, website, and profile links are clearly surfaced in plain text and linked text. What could not be fully confirmed from the public rendering interface was whether machine-readable structured data, schema, or metadata is perfectly synchronized with the visible page. So the trust claim “structured data is consistent with visible content” is NOT PUBLICLY VERIFIABLE from this audit alone.
Publisher attribution
This is where the site remains too indirect. The Contact page makes Michael Joseph Kappel the clear public contact and profile subject, and the related portfolio pages support that identity. But the publisher attribution of 2IA as a publication is still mostly inferential rather than explicit. The trust claim “the publisher’s identity is clear” is therefore PARTIALLY SUPPORTED: a careful reader can infer it, but a well-designed trust architecture should not make readers infer who is publishing a controversial or institutionally themed archive.
Corrections, right of reply, and functional public actions
Corrections findings
The main Corrections and Right of Reply page is substantively solid. It tells readers what may be reported: factual or quotation errors, source or legal-status problems, misleading or outdated presentation, privacy concerns, and right-of-reply issues. It tells readers what to provide: page URL, exact statement, explanation, proposed correction when known, supporting source, and optional contact information. It distinguishes correction, update, clarification, and right of reply in plain English. Those trust claims are all CLEAR AND USEFUL.
The downloadable correction template is also a real asset. It converts the corrections policy into a practical submission-preparation checklist and adds useful fields such as source title, issuing body, publication date, reference number, relevant section, downstream repair locations, and what should remain private. The trust claim “readers are told what evidence to provide and how to structure it” is OBSERVABLY TRUE.
The process is less complete on outcomes. The core page explains the types of changes, but it does not state a response SLA, review time window, publication threshold, appeal path, escalation path, or whether subjects receive acknowledgement. The page says “No public corrections have been recorded,” but it does not expose a visible corrections ledger or change log. The trust claim “a corrections log exists” is OBSERVABLY FALSE on the public evidence reviewed here. The trust claim “the process is functional” is only PARTIALLY SUPPORTED: a reader can email a documented correction, but there is no public proof of process execution or repair history yet.
The site does appropriately say what it will not do in one of the corrections-route subpages: it will not remove accurate public-interest information merely because it is inconvenient, treat unsupported demands as proof, publish private submission details without clear reason and permission, or promise a legal outcome. That is a good substantive boundary. But the page carrying that language is not the main corrections page; it sits inside a more template-like subpage structure. So the trust claim is PARTIALLY SUPPORTED as public policy language, but not well integrated into a simple, primary corrections standard.
Functional versus nonfunctional public actions
Several public actions are plainly functional in the ordinary sense. A reader can browse the site’s trust pages, read the methodology, open the public-records guidance, download the correction template, use direct email and phone contact, open the external professional and creative profile links, and navigate to the live upstream Daily Brief at InternationalIntelligence.org. Those are real public actions, not placeholders.
Several other public actions are explicitly nonfunctional or inactive, and the site is commendably straightforward about that. Newsletter signup is not active. Donation/support processing is not active. Volunteer intake is not active. The Daily Brief local synchronization route exists, but at the time of review it showed “Awaiting first synchronization” and “Not synchronized yet,” which means the local mirror was not then delivering a current edition. These trust claims are OBSERVABLY TRUE as status disclosures, and the candor is a strength.
The one caution is that search/discovery snippets still surface older navigation or boilerplate around support, newsletter, volunteer, and related routes. So while the current live pages are clear that these services are inactive, the public discovery record still gives a somewhat messier impression. That does not make the status pages untrustworthy; it means the current status is not yet cleanly propagated across all public entry points.
Internal-documentation bleed
This is one of the biggest editorial-quality problems visible in public. The main corrections page is reader-friendly. But multiple public subpages under the corrections route show repetitive, template-like, internally structured prose: “What To Check Next,” “Records Worth Pulling,” “What Would Change The Assessment,” “Reference Notes,” “Priority record,” “Source limit,” “Action record,” and repeated stock strings about public records, contracts, policies, and correction logs. The “Privacy Repair,” “Request A Correction,” and “Correction, Update, Or Source Note” pages all show this pattern. That is not hidden workflow leakage in the security sense, but it is unmistakably internal editorial scaffolding surfacing as public prose. The trust claim “the corrections route is fully reader-ready and free of internal workflow bleed” is MISLEADING.
The same issue appears on the volunteer-adjacent “Cooperating Experts Model” page, which contains repetitive dossier-like headings and stock “record/prove/check next” language. This again suggests either templated content generation or unfinished public packaging. For ordinary readers, that obstructs use because it feels less like a concrete route and more like a public dump of editorial prompt structure.
A narrower version of this appears on the Daily Brief page. Phrases such as “API first, validated fallbacks, and one local source of truth,” “conditional requests,” “atomic snapshots,” and “last-good retention” are not bad in themselves, but they are internal-system architecture language. Without a shorter reader summary first, they read more like implementation notes than trust summary. The trust claim “Daily Brief attribution and synchronization language is ordinary-reader friendly” is therefore PARTIALLY SUPPORTED.
Privacy policy, methodology, and public-records guidance
Privacy-policy findings
The Privacy Policy is intentionally narrow and largely tied to observable features of the live site. It says 2IA uses local assets and server-side rendering, does not add third-party analytics, advertising trackers, external fonts, session replay, heatmaps, or browser-side feed calls; that normal reading does not require an account; that standard server logs may exist; that no login or app cookie is required; that local storage may remember a preference; that core pages do not depend on CAPTCHA or embedded trackers; that no donation/newsletter/volunteer intake is active; and that ordinary contact happens through direct email/phone rather than a browser form. As a privacy document, that is commendably specific.
The truth status is mixed. The parts tied to visible site design are mostly supportable: there is no account requirement visible on the reviewed pages, no public contact form, and the inactive newsletter/support/volunteer pages match the policy’s statement that those collection routes are not active. Those claims are OBSERVABLY TRUE or PARTIALLY SUPPORTED.
By contrast, statements about the absence of third-party analytics, embedded services, and browser-side feeds, or about the exact handling of server logs, are not fully testable from public page rendering alone. They may be true, and nothing obvious in the visible pages contradicts them, but they remain NOT PUBLICLY VERIFIABLE at full technical depth from this audit alone. That is especially true for claims about what the application “does not add” and how the hosting environment retains logs.
The Daily Brief page is privacy-relevant and internally consistent with the privacy policy. It says readers receive a same-origin snapshot and that their browser does not contact the upstream publisher during page load. Conceptually, that aligns with the policy’s claim to avoid browser-side feed collection. But because no synchronized edition was available at the time of review, the trust claim “Daily Brief synchronization is privacy-preserving in practice” is NOT PUBLICLY VERIFIABLE from observed use, even though the architectural description is coherent.
Important privacy-policy omissions remain. Searches of the policy found no children’s privacy section and no policy-change/update section. The retention language is also hedged rather than specific: logs “should be” access-restricted and retained only as long as needed, but exact retention depends on deployment configuration. That is honest, yet incomplete. The trust claims “children’s privacy is addressed” and “policy changes are explained” are OBSERVABLY FALSE on the text reviewed. The trust claim “retention is clearly stated” is PARTIALLY SUPPORTED at best.
Methodology findings
The Methodology page is one of the site’s strongest trust components. It tells readers to identify the exact claim, trace source origin, test independence and corroboration, keep legal stages separate, state uncertainty and limitations, and correct the public record. It also defines claim labels such as Confirmed, Corroborated, Inferred, Disputed, Unknown, Public claim or allegation, and Court finding or legal disposition. The trust claim “the Methodology page helps ordinary readers understand source origin, corroboration, allegation versus finding, legal stage, and uncertainty” is CLEAR AND USEFUL.
The page also helps with the user’s requested distinction between historical versus current claims. It says the assessment should change when stronger evidence or a legal disposition becomes available, and it explicitly tells readers to explain whether time-sensitive facts may have changed. That is good evidence hygiene. The trust claim “the methodology marks historical/current uncertainty responsibly” is CLEAR AND USEFUL.
The page’s approach to neutrality is similarly well framed. It does not promise false balance; it says stronger evidence gets more weight and unsupported counterclaims do not create false balance. That is a legitimate editorial standard, clearly disclosed. The trust claim “the methodology explains neutrality without pretending all claims deserve equal weight” is CLEAR AND USEFUL.
The non-operational boundary is also strong. The Methodology page says AI may assist summary, comparison, clustering, or drafting, but that a human editor remains responsible for source, context, quotation, legal stage, privacy impact, and final claim. Related pages in the Anonymous collection explicitly exclude operational guidance, intrusion instructions, doxxing, and unlawful participation paths. The trust claim “the site has visible non-operational boundaries” is CLEAR AND USEFUL.
The main weakness is stylistic spillover. Terms such as “evidence-weighted” and “uncertainty-labeled” are acceptable in moderation, but across the site they recur so often that some pages start to feel like policy boilerplate rather than reader instruction. On the Methodology page itself, the balance is still good. On adjacent pages, the same vocabulary becomes clutter.
Public Records guidance
The main Public Records and FOIA page is genuinely useful. It tells readers which custodians might hold records, how to ask narrowly and then ladder up, what governance records to request beyond purchase orders, how to document denials, and how to publish a records note tied to what records prove. It also gives concrete first-request examples for surveillance, AI, vendor systems, and rights harms. The trust claim “the Public Records guidance helps ordinary readers understand what to ask for and why” is CLEAR AND USEFUL.
The Start Here page also supports this public-records orientation well by routing readers to records, historical events, current developments, corrections, and methodology, while offering a “Who Cares Wizard” for a records-and-responsibility map. The homepage reinforces that the wizard is “local-only,” not a secure drop, legal advice, crisis service, or reporting portal. As public explanation, that is good boundary-setting. The trust claim “the site gives practical records-first public-action guidance” is CLEAR AND USEFUL.
Where the public-records approach goes wrong is when the site shifts from the clean overview page into templated, dossier-like subpages. That pattern makes some public-records-adjacent or corrections-adjacent content feel internally generated and overprocessed. So the trust claim “the broader records/corrections help system is uniformly readable” is MISLEADING. The public-facing quality is uneven.
Confirmed contradictions, strong trust practices, remediation priorities, and proposed trust architecture
Confirmed contradictions
The clearest contradiction is between the current live identity and the public discovery-layer identity. Current rendered pages say “2IA — International Intelligence Archive,” while public search results for those same pages still surface “2IA — Two Identities Of Anonymous” and older project-description language. That is not a tiny cosmetic lag; it is a trust-signaling contradiction because readers will encounter both.
A second contradiction sits between the site’s inactive-service disclosures and the way older footer/navigation material still appears in search/discovery snippets. The live site now says newsletter signup, donation processing, and volunteer intake are inactive, yet public search/discovery results still surface those routes as part of broader site navigation. The status pages are honest; the public discoverability layer is stale.
A third contradiction is subtler: the site’s editorial voice strongly advocates minimization and careful identity exposure, yet the Contact page chooses to publish a residential mailing address. The page openly says that this was done at the publisher’s request, so it is not hidden or accidental. Still, as a trust-design matter, it sits uneasily beside repeated sitewide minimization language. That is less a factual contradiction than a privacy-design tension.
Strong trust practices
The strongest practice on the site is boundary clarity where it is present. The site repeatedly says it is independent, information-only, non-operational, not a secure-drop service, and not affiliated with power centers or Anonymous. That is good public-interest publishing hygiene.
The site’s Methodology is also unusually mature for a public-facing archive. It distinguishes allegation from finding, arrest from conviction, source repetition from corroboration, and inference from direct proof. That substantially improves institutional credibility.
The Corrections route is stronger than average because it distinguishes correction, update, clarification, and right of reply instead of treating all post-publication changes as the same. The downloadable template is practical rather than merely performative.
The privacy stance is also stronger than average in one key respect: inactive collection routes are not hidden behind decorative forms. The site plainly says when support, newsletter, and volunteer intake are inactive, and it does not pretend that ordinary email is secure.
Prioritized remediation plan
First, the site should complete the rebrand at the public discovery layer. That means aggressively aligning page titles, descriptions, structured metadata, canonical search snippets where possible, legacy-brand references, and footer text so that “Two Identities Of Anonymous” stops being the primary discovery-layer identity for current pages. This is the single most important institutional-trust fix because it affects first contact.
Second, the site should add a plain masthead publisher statement to the homepage, About page, footer, and Contact page. Something as simple as “Published by Michael Joseph Kappel” or “2IA is independently published by Michael Joseph Kappel” would remove unnecessary inference without changing the site’s mission. That would materially improve the clarity of publisher attribution.
Third, the site should publish a real corrections ledger even if it is empty. “No public corrections have been recorded” is not the same thing as a visible change log architecture. A public corrections page should be able to show entries, timestamps, affected URLs, type of repair, and whether a right of reply was added.
Fourth, the site should prune or rewrite the templated, dossier-like subpages under corrections and volunteer/public-records-adjacent routes. Reader-facing trust pages should not read like internal prompts, QA checklists, or editorial scaffolds. The public material should keep the substance but lose the visible template residue.
Fifth, the Privacy Policy should add missing basics: children’s privacy, policy-change notice, clearer retention periods where possible, and a simpler privacy matrix explaining what is collected by page type.
Sixth, the Contact page should probably separate editorial contact from professional portfolio/profile content. The current page is usable, but a dedicated editorial contact card plus a separate “About the publisher” profile page would create cleaner institutional boundaries and reduce the sense that the publication contact page doubles as a services page.
Proposed reader-facing trust architecture
A stronger, reader-facing trust architecture for 2IA would have six visible elements.
A masthead block should appear sitewide and name the archive, the publisher, the editorial scope, and the non-affiliation statement in one compact unit. Right now, mission clarity is better than publisher clarity.
A publisher card should state who publishes 2IA, how to contact the publication, and what the institutional relationship is to MikeKappel.com, InternationalIntelligence.org, and MichaelJosephKappel.com. The Daily Brief page already does some of this work for the sister publication; the same clarity is needed for the site as a whole.
A status center should unify the currently separate “Newsletter Status,” “Support Status,” “Volunteer Status,” and Daily Brief synchronization state into one plainly dated public operations page. That would reduce scattered status signaling and make inactive functions easier to interpret.
A corrections ledger should sit next to the corrections policy and template. Policy without visible execution is weaker than policy with even a few small, dated examples.
A privacy matrix should distinguish passive reading, local-only tools, outbound links, ordinary email/phone contact, and Daily Brief synchronization behavior, showing for each route what is known, what is not known, and what is not collected. The current Privacy Policy has the ingredients, but not yet the clearest structure.
Finally, a metadata hygiene program should treat search/discovery snippets as part of the publication itself. For an institutional-trust archive, outdated public metadata is not secondary; it is part of the reader’s first evidence record. Until those discovery strings stop surfacing the legacy brand and older boilerplate, the rebrand remains incomplete in practice.